Behavioral Governance Is the New IAM: Reading Akamai's Agentic Threat Landscape
💡 Tool Tip:API Key Rotator, JWT Decoder, Regex Tester
Akamai has published its twelfth State of the Internet (SOTI) security report, Speed, Scale, and Nonhuman Identity: The Agentic Threat Landscape, aimed squarely at CISOs. Its central claim is blunt: securing a modern business has evolved from identity and access management for people into behavioral governance over nonhuman entities. The report highlights two hard problems, the difficulty of setting guardrails for autonomous agents, and the speed at which AI models discover vulnerabilities, often outpacing human patch cycles. Here is what the data actually says and which controls follow from it.
1. The Data: Risk Changed Protagonists
Three numbers will get quoted most. First, more than 40% of enterprise users have installed AI-powered browser extensions on their devices, and 25% of those extensions altered their permissions within 12 months. The read-only summariser you approved yesterday may be able to read every page you open today. Second, more than 6% of chatbot conversations contain sensitive information, primarily personally identifiable information, and reporting on the same research notes that a large share of those interactions happen through unmonitored personal accounts. Third, Akamai is explicit that attackers are following enterprises into agentic AI, with API attacks shifting away from traditional web attacks toward behaviour-based threats.
# Nonhuman identity: scope an agent the way you would scope a
# contractor, not the way you scope the employee who hired it.
# Broad inherited permissions are what turn a prompt injection into a breach.
AGENT_SCOPES = {
# Least privilege per agent, per resource. No wildcards on data.
"invoice-agent": ["invoices:read", "vendors:read", "erp:write:invoices"],
"support-agent": ["kb:read", "tickets:read", "tickets:write:notes"],
"browser-agent": ["web:fetch"], # no cookie jar, no saved sessions
}
def authorize(agent_id: str, action: str, resource: str) -> bool:
allowed = AGENT_SCOPES.get(agent_id, [])
if action not in allowed:
audit("denied_scope", agent=agent_id, action=action, resource=resource)
return False
# Scopes are per-agent and per-session; never accumulate across turns.
return TrueRisk shifts from human identity to autonomous nonhuman entities
2. Why Behavioral Governance Replaces IAM
Classic IAM assumes a stable subject. A person has a set of entitlements, entitlements change rarely, and audits can run quarterly. Agents break that assumption. The second headline finding is that models find vulnerabilities faster than human patch cycles close them, and an agent's effective capability is a function of its current prompt and context, not of a static grant. The assistant that could only read tickets yesterday can write to the database today because someone attached one more MCP server. So the control point has to move from who you are to what you are doing. Code sample 4 expresses that as a behavioural policy: 120 reads per hour is baseline, four times that triggers step-up authentication, six times the normal number of distinct customers triggers throttling and a notification, which is the classic shape of a bulk export. Akamai's finding that roughly 61% of API attacks in 2025 involved unauthorised workflows and abnormal activity, up from 30% in 2024, is the same story told from the attacker's side.
// The browser is the new unprotected workspace. If you cannot list the
// extensions, you cannot answer "who can read this page". Inventory first,
// then constrain what an extension may change about itself.
const reviewQueue = await endpointAgent.query({
kind: "browser_extension",
where: {
flags_ai_powered: true,
permissionChangeWithinDays: 365, // Akamai found 25% changed in 12 months
},
fields: ["host", "user", "extensionId", "permissionsBefore", "permissionsAfter",
"knownCveCount"],
});
for (const ext of reviewQueue) {
const risky =
ext.permissionsAfter.includes("<all_urls>") ||
ext.permissionsAfter.includes("debugger") ||
ext.knownCveCount > 0; // extensions carried ~60% higher CVE risk
await ticket({ ext, severity: risky ? "high" : "review", action: "scope_or_remove" });
}3. The Browser as an Unprotected Workspace
The report calls the browser a critical, unmonitored attack surface, and the reasoning is not hard to follow. When agents need to act on the web, browser extensions become their hands and eyes, and extension permission models are far looser than those of backend services. Code sample 2 lays out the practical order of operations: inventory first, then constrain. The query filters on whether an extension is flagged as AI-powered and whether it changed permissions within the last year, which map directly onto the 40% and 25% figures. The risk test is deliberately simple, meaning an extension that acquired all-sites access, requested the debugger permission, or carries a known CVE. Reporting on the same research puts the increased exposure to known CVEs in AI extensions at roughly 60% versus standard extensions, which turns inventory from a compliance chore into a risk action.
# Chatbot sessions are an exfiltration channel that no DLP rule saw coming.
# 6% of conversations on enterprise devices contain sensitive data, and
# about half of those interactions happen through personal accounts.
# Decide the rule once, then enforce it before the prompt leaves the device.
SENSITIVE = (
r"(?i)(account|invoice|card)[_ -]?(no|number)[: ]?[0-9]{6,}",
r"(?i)aws_secret_access_key[ =:]+[A-Za-z0-9/+=]{40}",
r"[0-9]{3}-[0-9]{2}-[0-9]{4}",
)
def inspect_prompt(prompt: str, account_type: str) -> dict:
hits = [p for p in SENSITIVE if re.search(p, prompt)]
if hits and account_type == "personal":
# Personal accounts are unmonitored; do not let corporate data in.
return {"action": "block", "why": "corporate data via personal account"}
if hits:
return {"action": "redact_then_send", "patterns": len(hits)}
return {"action": "allow"}Over 40% installed AI extensions; 25% changed permissions in a year
4. Conversation Is the New Exfiltration Channel
More than 6% of conversations on enterprise devices contain sensitive data, and the real meaning of that number is a historical blind spot in DLP. Old rules watched email, uploads, and the clipboard, and rarely treated what you paste into a chat box as an egress event. Code sample 3 shows a workable shape: define sensitive patterns centrally, then route by account type, blocking outright when corporate data would leave through a personal account that nobody monitors, and redacting before sending from a managed account. The point is not regex perfection; it is treating the personal-account path as its own default-deny route. Code sample 6 applies the same instinct to agents by running an access regression that asks each nonhuman identity to reach data it has no business reaching, where the expected result is a denial.
# Agents discover vulnerabilities faster than human patch cycles close them.
# That is Akamai's second headline finding. Treat "new CVE published" as an
# event with a deadline, and let the inventory drive who gets paged.
def patch_deadline(cve: dict) -> dict:
# Gateways, MCP servers and browser extensions that agents can reach
# get an SLA proportional to exploitability, not to convenience.
days = 3 if cve["actively_exploited"] else 7 if cve["cvss"] >= 9.0 else 30
owners = inventory.owners_of(cve["package"], kinds=("agent", "mcp", "extension"))
return {"cve": cve["id"], "dueInDays": days, "owners": owners}
def sweep(cves):
for cve in cves:
d = patch_deadline(cve)
if not d["owners"]:
# Unowned is worse than unpatched: nobody will ever patch it.
escalate("orphan dependency reachable by agents: " + cve["id"])
else:
notify(d["owners"], d)5. Patch Cycles Cannot Keep Up
The other half of the report is a velocity problem: models find vulnerabilities faster than people patch them. Code sample 4 turns that into an SLA, three days for actively exploited issues, seven days at CVSS 9.0 or above, thirty days otherwise, and it routes the work by who can actually reach the dependency, counting agents, MCP servers, and browser extensions alike. There is a detail here that teams overlook: an unowned dependency is more dangerous than an unpatched one, because nobody will ever patch it, which is why the sample escalates orphan dependencies immediately. This connects back to least privilege for nonhuman identity in code sample 1. When you cannot determine what an agent should be allowed to do, the correct default is that it is allowed to do nothing.
// Behavioral governance means policy on what an agent does, not only on
// who it is. An agent that suddenly starts reading an unusual number of
// records is a signal even if its credentials are perfectly valid.
const behavioralPolicy = {
agentId: "support-agent",
baseline: { readsPerHour: 120, distinctCustomersPerHour: 40, exportsPerDay: 0 },
rules: [
{ when: "readsPerHour > 4 * baseline.readsPerHour", then: "step_up_auth" },
{ when: "distinctCustomersPerHour > 6 * baseline.distinctCustomersPerHour",
then: "throttle_and_notify" }, // classic bulk-export shape
{ when: "newEgressHost and !allowlisted", then: "block" },
],
evidence: ["traceId", "tool", "resourceIds", "promptHash"], // keep the why
};
// 61% of API attacks in 2025 involved unauthorized workflows and abnormal
// activity, up from 30% in 2024. Behaviour is where the attack now lives.More than 6% of chatbot conversations carry sensitive information
6. An Order of Operations for Security Teams
First, give every agent its own identity and a least-privilege scope rather than inheriting the full session of whoever invoked it, as in code sample 1. Second, fold browser extensions and MCP servers into one asset inventory, prioritising anything AI-powered that changed permissions in the past year, as in code sample 2. Third, define a sensitive-data policy for conversation channels with a default-deny path for personal accounts, as in code sample 3. Fourth, tie patch SLAs to reachability and escalate orphan dependencies, as in code sample 4. Fifth, establish behavioural baselines and respond to deviation with step-up authentication, throttling, or a block, as in code sample 5. Sixth, run the unauthorised-reach regression on a schedule so that cannot be reached is an assertion you verify instead of an assumption you hold, as in code sample 6. Akamai's Chief Security Officer Boaz Gelbord summarises the moment as an everything, everywhere, all at once problem with a triple threat: internal AI usage, AI wired into customer-facing products, and AI-driven attacks. The controls do not need to be as sweeping as that sentence, but they do need to be that specific.
📌 Frequently Asked Questions
What is the full name of the Akamai report?
Speed, Scale, and Nonhuman Identity: The Agentic Threat Landscape. It is part of Akamai's twelfth-year State of the Internet (SOTI) security report series and is targeted at a CISO audience.
How does behavioral governance differ from traditional IAM?
Classic IAM assumes a stable subject whose entitlements change rarely. An agent's effective capability shifts with its prompt and context, so the control point moves from who the identity is to what it is doing, using behavioural baselines to flag deviation.
How specific is the browser risk?
More than 40% of enterprise users have installed AI-powered browser extensions, and 25% of those extensions altered their permissions within 12 months. Akamai describes the browser as a critical, unmonitored attack surface.
How significant is data exposure through chatbots?
More than 6% of chatbot conversations contain sensitive information, primarily personally identifiable information, and reporting on the research notes that many such interactions occur through unmonitored personal accounts.
What does the report advise CISOs to do?
Give nonhuman identities their own least-privilege scopes, fold browser extensions and MCP servers into one asset inventory, set an explicit sensitive-data policy for conversation channels, tie patch SLAs to reachability, and baseline agent behaviour with a defined response to deviation.
🔧 Recommended Tools
📚 Sources
- Akamai — Akamai Report: Securing Agentic AI Requires Shift to Behavioral Governance (press release)
- Akamai Blog — Beyond Identity: Governing the Agentic Enterprise
- Akamai — Speed, Scale, and Nonhuman Identity: The Agentic Threat Landscape (SOTI report)
- Akamai — Apps, APIs, and DDoS 2026 security report (PDF)
- Technology Magazine — Akamai Report: Governing Non-Human Agentic AI Browser Risks (Sep 25, 2026)